Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Consent Records

Consent Log

Also known as: Consent Record, Consent Logging, User Consent Record, Record of Consent
Simply put

A consent log is a record of the choices users make when they interact with a cookie consent banner or similar mechanism, such as agreeing to or refusing the use of their data. It typically captures information that lets an organization look up a particular user's decision later. Consent logs are commonly generated and stored by consent management tools built into websites.

Formal definition

A consent log is a stored record of consent (and, where applicable, refusal or withdrawal) captured through a consent mechanism such as a cookie banner or preference center. In practice, consent management platforms and website plugins log each interaction along with metadata intended to enable later lookup of a user's specific choices; the exact fields captured vary by tool and configuration. Consent logging is generally understood to support the accountability and demonstrability expectations associated with consent under EU frameworks, but the precise records, retention periods, and evidentiary standards required depend on the applicable legal regime and regulator guidance, which this definition does not resolve. Maintaining a consent log is a technical and organizational measure that supports compliance but does not by itself guarantee that consent was validly obtained.

Why it matters

Under EU frameworks such as the GDPR, controllers are generally expected to be able to demonstrate that they obtained valid consent where consent is the basis for processing personal data. A consent log supports this accountability expectation by preserving a record of the choices users made when interacting with a cookie banner or preference center, so that an organization can later look up a particular user's decision. Without such a record, an organization may struggle to show whether, when, and to what a user agreed or objected.

It is important not to overstate what a consent log achieves. Maintaining a log is a technical and organizational measure that supports compliance, but it does not by itself guarantee that consent was validly obtained. If the underlying consent mechanism was flawed, for example, if it relied on pre-ticked boxes, implied consent, or a design that did not meet the freely given, specific, informed, and unambiguous standard applied in most EU jurisdictions, a log will simply record an interaction that may not amount to valid consent.

The precise records, retention periods, and evidentiary standards that regulators expect vary by legal regime and by data protection authority guidance, and these questions are not resolved by the mere existence of a log. Requirements also differ outside the EU: frameworks such as certain US state privacy laws often rely on opt-out mechanisms rather than opt-in consent, which affects what a record needs to capture. Organizations should therefore treat consent logging as one part of a broader compliance approach rather than a standalone solution.

Who it's relevant to

Privacy and data protection officers
Consent logs are a key tool for meeting the accountability and demonstrability expectations associated with consent under EU frameworks. DPOs and privacy teams should understand what their consent management tools record, how long records are retained, and whether those records are adequate to support the organization's chosen legal basis and applicable regulator expectations.
Legal and compliance counsel
Counsel advising on cookie compliance need to assess whether a consent log provides sufficient evidence of valid consent, bearing in mind that a log records an interaction but does not establish that the consent standard was met. They should also account for differences across regimes, including opt-out-based frameworks in some US states, where record-keeping needs differ from EU opt-in models.
Web developers and CMP administrators
Those implementing and configuring consent management platforms or cookie banner plugins are responsible for enabling and configuring logging so that interactions and preferences are captured and stored in a way that supports later lookup. Because captured fields and retention settings vary by tool, developers should verify the tool's behavior against the organization's compliance requirements.
Marketing and analytics teams
Teams relying on analytics, advertising, or other non-essential cookies, which typically require prior consent under EU law, depend on accurate consent records to confirm which users have agreed to which processing. Consent logs help ensure that tracking technologies are only activated in line with recorded user choices.

Inside Consent Log

Consent identifier
A unique reference associated with a given consent event, typically enabling a specific record to be located and, where necessary, linked to a user, session, or device without necessarily storing directly identifying information.
Timestamp
The date and time the consent was given, withdrawn, or updated, which supports demonstrating when a particular choice was made and how long it has been relied upon.
Scope of consent
A record of which cookie categories or purposes (for example analytics, advertising, or functional) the user accepted or rejected. In most EU jurisdictions strictly necessary cookies are treated as exempt and would not depend on such consent.
Consent state or choices
The specific choices captured, including granular acceptances and refusals, and any subsequent withdrawal, so the current and historical state can be reconstructed.
Version of the consent notice or configuration
A reference to the banner text, purpose descriptions, or CMP configuration in effect at the time, helping to show what information the user was presented with when consenting.
Method and evidence of the affirmative action
Details of how consent was collected (for example the interface used and the action taken), relevant to demonstrating that consent was given through a clear affirmative action rather than pre-ticked boxes or implied from continued browsing, which are widely considered non-compliant in the EU.
Signal source where applicable
Where relevant, an indication of whether a choice reflected a user interaction with a banner or an automated signal such as Global Privacy Control, noting that the treatment of such signals varies between jurisdictions and frameworks.

Common questions

Answers to the questions practitioners most commonly ask about Consent Log.

Does keeping a consent log by itself make our cookie practices compliant?
No. A consent log is a record-keeping mechanism that supports your ability to demonstrate accountability, but it does not, on its own, establish compliance. If the underlying consent was not validly obtained, for example, if it was not freely given, specific, informed, and unambiguous through a clear affirmative action as required under the GDPR, then logging that interaction does not cure the defect. The log evidences what happened; it does not validate whether what happened met legal standards. Compliance depends on the design of your consent flow, the categories of cookies involved, and the applicable legal regime, and typically requires legal judgment beyond the existence of a log.
Is a consent log the same thing as consent itself?
No. Consent is the user's freely given, specific, informed, and unambiguous agreement, expressed through a clear affirmative action. A consent log is the stored record of that event and its surrounding details. The two are distinct: you can have a technically complete log entry for an interaction that did not amount to valid consent (for instance, one captured through a pre-ticked box or implied from continued browsing, both of which are widely considered non-compliant in the EU). Conversely, valid consent that is poorly logged may leave you unable to demonstrate accountability. Treat the log as evidence of consent, not as consent.
What details are typically captured in a consent log?
Practice varies, but consent logs commonly aim to record enough detail to demonstrate that valid consent (or a valid opt-out, depending on the regime) occurred. This may include an identifier for the user or device, the categories of cookies or purposes consented to or declined, the timestamp, the consent interface or version presented, and the specific choice made. Some organizations also retain the wording or version of the notice shown at the time. The precise fields depend on your consent management setup and the accountability expectations of the relevant data protection authority; there is no single universally mandated schema.
How long should consent records be retained?
There is no single fixed retention period that applies everywhere. Retention should generally be guided by the purpose of keeping the record, namely, being able to demonstrate accountability, balanced against data minimization principles under the GDPR, which caution against keeping personal data longer than necessary. Some organizations retain logs for as long as the consent remains relied upon plus a further period to address potential disputes or regulatory inquiries. The appropriate period may differ by jurisdiction and by the sensitivity of the data involved, so this is an area where legal judgment is typically needed rather than a default value.
How do consent management platforms (CMPs) support consent logging?
Many CMPs provide built-in functionality to capture and store consent interactions, and those operating within frameworks such as the IAB Transparency and Consent Framework (TCF) may encode consent choices in a structured signal. This can help operationalize record-keeping at scale. However, a CMP supports compliance rather than guaranteeing it: you remain responsible for configuring the tool correctly, ensuring the logged interactions reflect validly obtained consent, and confirming the records meet the accountability expectations applicable to your jurisdictions. The presence of a CMP-generated log does not substitute for legal review of your consent design.
Should consent logs also capture opt-out signals such as Global Privacy Control?
Where you operate under regimes that rely on opt-out mechanisms, such as certain US state privacy laws, recording the receipt and handling of signals like Global Privacy Control can be relevant to demonstrating that you honored user choices, in the same way that opt-in consent is logged under EU-style frameworks. Because the legal basis and the nature of the user action differ between opt-in and opt-out regimes, the fields and interpretation of the record may differ as well. What a log needs to demonstrate depends on which framework governs a given user, so scoping your logging to the applicable regime is generally advisable.

Common misconceptions

Keeping a consent log by itself proves compliance.
A consent log is evidence that can support the ability to demonstrate consent, but it does not on its own establish that the consent collected was valid or that the underlying banner and processing were lawful. Logging tools and CMPs support compliance rather than guaranteeing it, and legal judgment remains necessary.
One consent log satisfies the requirements of every jurisdiction.
Requirements differ across regimes. EU and UK approaches generally rely on prior opt-in consent for non-essential cookies, while several US state laws such as the CCPA and CPRA often operate on an opt-out basis. What a log should capture and how choices are interpreted therefore vary by geographic and legal scope.
A consent log only needs to record acceptances.
To reflect the full picture, records typically need to capture refusals and withdrawals as well, since the ability to withdraw consent as easily as it was given is central to the GDPR standard, and being able to show a user later declined or reversed a choice can be as important as showing they accepted.

Best practices

Record the details needed to reconstruct each consent decision, including the timestamp, the categories or purposes affected, the specific choices made, and the version of the notice or CMP configuration in effect at that time.
Log withdrawals and changes to consent, not just initial acceptances, so the current state and full history can be demonstrated and so withdrawal is honored promptly.
Define and document retention periods for consent records that are proportionate and consistent with data minimization, avoiding indefinite storage of more identifying information than is needed to demonstrate consent.
Align what you log with the applicable legal regime, recognizing that EU and UK opt-in expectations differ from opt-out frameworks such as the CCPA and CPRA, and document the geographic scope your logging is designed to support.
Treat the CMP or logging tool as support rather than a substitute for legal review; validate that the affirmative-action mechanism and banner it records would themselves be considered valid, and involve privacy or legal counsel in that assessment.
Periodically review logging practices against evolving data protection authority guidance, since enforcement positions change and previously accepted approaches may need to be revisited.
Promotional banner for the Penetration Report Template Kit